CVE-2014-9447: Path Traversal
Directory traversal vulnerability in the readlongnames function in libelf/elfbegin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9447?
CVE-2014-9447 is considered to have a high severity due to its potential for remote attackers to exploit the vulnerability.
Which versions of elfutils are affected by CVE-2014-9447?
CVE-2014-9447 affects elfutils versions 0.152 and 0.161.
How can I fix CVE-2014-9447?
To fix CVE-2014-9447, upgrade to a patched version of elfutils that addresses this directory traversal vulnerability.
What type of vulnerability is CVE-2014-9447?
CVE-2014-9447 is a directory traversal vulnerability that allows attackers to write to arbitrary files.
How does CVE-2014-9447 allow exploitation?
CVE-2014-9447 allows exploitation via a crafted archive containing a slash, enabling remote attackers to disrupt file security.